Tune rules based on rook analysis #116
Merged
Chainguard Enforce / Enforce - Commit Signing
succeeded
Apr 11, 2024 in 0s
Successfully verified commit signature.
CLAIM | DESCRIPTION | |
---|---|---|
✅ | Found Git signature | |
✅ | Validated Git signature | |
✅ | Validated Rekor entry | |
✅ | Allowed by policy |
Details
Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 667170604527731849768486977346734634578567778138 (0x74dcf6efa4815006e148cb2206479e6c8b084f5a)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Apr 11 17:54:49 2024 UTC
Not After : Apr 11 18:04:49 2024 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
6e:8b:1d:d7:fd:59:5e:f1:3a:4a:64:3c:97:b3:5d:
af:7c:f3:94:60:8e:30:4d:06:d1:65:53:59:25:d3:
0e:07
Y:
8a:b8:6a:70:3e:f2:a8:c3:95:9d:51:2b:7d:08:fa:
8f:68:7b:e6:61:22:d1:af:09:31:4c:ed:b5:86:f9:
f2:82
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
13:C2:EC:BB:42:10:27:BD:B9:9E:DF:3E:19:3B:78:FC:76:47:DD:2F
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:[email protected]
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHoAeAB2AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABjs5MRq0AAAQDAEcwRQIgcGYrrSpNRtLGttyGmgkziY+1s2gQ7f/Z0dYt/wlH0HACIQDqpK4nH4GffvH6E2jSxskvjBdlqa8OOzfKAiVUZbVLew==
Signature Algorithm: ECDSA-SHA384
30:66:02:31:00:da:3c:93:8e:80:04:0b:2a:f6:72:1f:37:29:
af:7a:e1:36:87:57:5f:4e:44:1f:3d:f6:e1:e9:4a:d4:67:ed:
ec:cb:19:b6:b7:72:0f:d0:03:01:17:e7:81:fc:84:5d:ea:02:
31:00:f8:72:08:de:de:23:73:d4:12:ed:78:85:25:14:ed:b4:
51:3d:e8:5b:77:0f:6e:6e:54:42:ce:9a:42:67:4c:b2:1f:9a:
0b:a4:70:9a:51:2f:8b:b5:41:cc:03:43:f4:78
Rekor Entry
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiIxZjE3MDI2ODJkNjEyOTA2MTM3YjZlZDM1NjJjNzAwNGMwZWYzOTE2ZjM3ZmQ0MzNjYzgwMjdkZjRkMDg1NjkyIn19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FVUNJUUQwMnE2WnEvTlQ2V2REVFF6RnMrZzg2cUJtbkxQM2d3R05HK1dTRFBPd2tBSWdPbU56UWVTQ1cxMmFRSXFXMnpVY2xFdXVoc3ppRXhoNFptd3FSNVc3TkFvPSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTjVha05EUVdzclowRjNTVUpCWjBsVlpFNTZNamMyVTBKVlFXSm9VMDF6YVVKclpXVmlTWE5KVkRGdmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFJkMDVFUlhoTlZHTXhUa1JSTlZkb1kwNU5hbEYzVGtSRmVFMVVaM2RPUkZFMVYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZpYjNOa01TOHhXbGgyUlRaVGJWRTRiRGRPWkhJemVucHNSME5QVFVVd1J6QlhWbFFLVjFOWVZFUm5aVXQxUjNCM1VIWkxiM2MxVjJSVlUzUTVRMUJ4VUdGSWRtMVpVMHhTY25kcmVGUlBNakZvZG01NVozRlBRMEZYTkhkblowWnhUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZGT0V4ekNuVXdTVkZLTnpJMWJuUTRLMGRVZERRdlNGcElNMU00ZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDBobldVUldVakJTUVZGSUwwSkNVWGRGYjBWUlpFVkNhbUZIUm5CaWJXUXhXVmhLYTB4dFVteGtha0Z3UW1kdmNrSm5SVVZCV1U4dlRVRkZRZ3BDUW5SdlpFaFNkMk42YjNaTU1rWnFXVEk1TVdKdVVucE1iV1IyWWpKa2MxcFROV3BpTWpCM1MzZFpTMHQzV1VKQ1FVZEVkbnBCUWtOQlVXUkVRblJ2Q21SSVVuZGplbTkyVERKR2Fsa3lPVEZpYmxKNlRHMWtkbUl5WkhOYVV6VnFZakl3ZDJkWmIwZERhWE5IUVZGUlFqRnVhME5DUVVsRlprRlNOa0ZJWjBFS1pHZEVaRkJVUW5GNGMyTlNUVzFOV2tob2VWcGFlbU5EYjJ0d1pYVk9ORGh5Wml0SWFXNUxRVXg1Ym5WcVowRkJRVmszVDFSRllYUkJRVUZGUVhkQ1NBcE5SVlZEU1VoQ2JVczJNSEZVVldKVGVISmlZMmh3YjBwTk5HMVFkR0pPYjBWUE15OHlaRWhYVEdZNFNsSTVRbmRCYVVWQk5uRlRkVXA0SzBKdU16ZDRDaXRvVG04d2MySktURFIzV0ZwaGJYWkVhbk16ZVdkSmJGWkhWekZUTTNOM1EyZFpTVXR2V2tsNmFqQkZRWGROUkdGUlFYZGFaMGw0UVU1dk9HczBOa0VLUWtGemNUbHVTV1pPZVcxMlpYVkZNbWd4WkdaVWExRm1VR1ppYURaVmNsVmFLek56ZVhodE1uUXpTVkF3UVUxQ1JpdGxRaTlKVW1RMlowbDRRVkJvZVFwRFRqZGxTVE5RVlVWMU1UUm9VMVZWTjJKU1VsQmxhR0prZHpsMVlteFNRM3B3Y0VOYU1IbDVTRFZ2VEhCSVEyRlZVeXRNZEZWSVRVRXdVREJsUVQwOUNpMHRMUzB0UlU1RUlFTkZVbFJKUmtsRFFWUkZMUzB0TFMwSyJ9fX19",
"integratedTime": 1712858089,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 84995761,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 2605736670972794746\n80846516\ncW/NMj3uVzM4qpjm8SwHjVMdxp0eS2IsXSl2HnSiVEc=\n\n— rekor.sigstore.dev wNI9ajBFAiA4XhQPKVJtkc2Ktz0Tf7KsVVt93cdIe8p5MiBYGtlpKgIhAMR9WvrX7XVFGIX65jKPx8vpYg+sIqtXZaUeI1ptF7dJ\n",
"hashes": [
"d6f6dd4730dccc44dcfe86ed3868ffb9529ec1baba3ac87d68749db23a9664fe",
"ff2b153e79f1091c8c108b48aac06f7334af534dc0d191c89872b5278cebed55",
"ca22d49d68bf71b444b3b449f2c83b39ae78c06ffa5b914d87455a4b38c7b4d2",
"cb0ef2dc60b47fe837cdd84be66bb9433b4a936b447c220629a0b18924a277aa",
"4b4f3fa56700e64efeed3a40dc87d7e7733617bc6f3968c587b1467867915c18",
"6cbc443fd068d4e02d36596397ad635a25d21aeb0d0c84277927577d690d7d75",
"0ac7ce7ffdedaf4d24b871e0ad3b4c4d3bbc02214036e6d21fc1e326b907e233",
"89bb52437a0ca83f148bd2a6f8242bdfa2d2a18d022707a4f7bd2d1df70b01ce",
"9596bdc7041fbc50edd40457f4dbfabd4a6e920f004c75e56756dd7ea37421cf",
"806afa247cd23bfaa648498af2dfa69f21ea04b55cb7f0037d6b7392c86a76ba",
"3b43b6e2474be3ef28cae3d69954abbfb9164640f567bd35868b32744b760d35",
"533f7e3c325ccc04ce4ed0f0768736be21e8ba62e32a16389dac9d4748380e34",
"4a9bb82c4cfcaa12dc3c22076e9105b9c49eb3b7f0f4ed656a592d657b9f98c0",
"0a1e4e42f8651e64fd9535583710c340a01ab6b9cdfc3387773b04125c315606",
"6bdafee8fa36becbb4cad8667c20fb7aaa160579fee62466023b1ac0611965b7",
"4ac348e086ef5b1bc16fa258b2e856f23a63ee81960872dfea772b1267e365ef",
"ad85259c3e30a63dfb01336a2f58a9e5e071a80dfa0e2c916f2d24fa250e32bb",
"4d8fabb0af59a4079546b996408cce25453b84008683a51fe27e7f78f9470d85",
"b66caf5e8b1f7b1fcd5a06ad2371b53dc1ae6524eb4775aed563ba31d565b426",
"0c60918bcf6f554648566bcad8014e99e32a101ea7f91f7a65efaf8d601906fc",
"f7c7a7ccc682fb1e6808cbc8650039cfcbeed9aa4330216f13ff77e4d7ee3f0f"
],
"logIndex": 80832330,
"rootHash": "716fcd323dee573338aa98e6f12c078d531dc69d1e4b622c5d29761e74a25447",
"treeSize": 80846516
},
"signedEntryTimestamp": "MEUCIB9dZscrrJrJE2hBj9R5U4Eoeb6g3PahjtP9SQkvOXfvAiEApJk+wXiEUaCY6lEM43bqaeSTQVFcZSgNvpks3Dy3BO4="
}
}
Loading